Voila le nouveau rapport! :)
ComboFix 09-04-29.01 - Marie 29/04/2009 20:18.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.282 [GMT 2:00]
Lancé depuis: c:\documents and settings\Marie\Bureau\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Internet Explorer\fxavx.ini
c:\windows\patch.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\rnaph.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WINDOWS_LOG
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-28 au 2009-4-29 ))))))))))))))))))))))))))))))))))))
.
2009-04-29 11:48 . 2009-04-29 11:48 -------- d-sh--w c:\documents and settings\Marie\UserData
2009-04-29 09:54 . 2009-04-29 10:17 -------- d-----w C:\UsbFix
2009-04-29 09:41 . 2009-04-29 09:41 -------- d-----w C:\rsit
2009-04-29 09:08 . 2009-04-29 09:08 -------- d-----w c:\program files\Fichiers communs\Adobe AIR
2009-04-29 08:48 . 2009-04-29 08:48 -------- d-----w c:\program files\Trend Micro
2009-04-14 18:17 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 18:17 . 2009-03-06 14:20 286720 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-14 18:17 . 2009-02-09 11:23 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-14 18:17 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-14 18:17 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-14 18:17 . 2009-02-09 10:53 685568 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-14 18:17 . 2009-02-09 10:53 735744 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-14 18:17 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 18:17 . 2009-02-09 10:53 739840 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 18:12 . 2008-12-16 12:31 354304 -c----w c:\windows\system32\dllcache\winhttp.dll
2009-04-14 18:12 . 2008-04-21 21:15 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-29 09:07 . 2004-01-17 09:40 -------- d-----w c:\program files\Fichiers communs\Adobe
2009-04-29 08:26 . 2009-01-17 12:54 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-29 08:23 . 2005-01-06 10:31 -------- d-----w c:\program files\Macromedia
2009-04-29 08:23 . 2004-01-17 09:20 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-29 08:23 . 2005-01-06 10:32 -------- d-----w c:\program files\Fichiers communs\Macromedia
2009-04-29 05:41 . 2004-01-17 09:49 77038 ----a-w c:\windows\system32\perfc00C.dat
2009-04-29 05:41 . 2004-01-17 09:49 474316 ----a-w c:\windows\system32\perfh00C.dat
2009-04-15 01:02 . 2005-12-02 20:33 -------- d-----w c:\program files\Microsoft ActiveSync
2009-04-06 13:32 . 2009-01-17 12:55 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2009-01-17 12:55 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-31 16:47 . 2004-04-27 21:16 -------- d-----w c:\program files\Java
2009-03-13 17:08 . 2009-03-13 17:08 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-03-13 17:08 . 2009-03-13 17:08 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-03-13 17:03 . 2009-03-12 18:41 -------- d-----w c:\program files\Nokia
2009-03-13 16:58 . 2009-03-12 18:43 -------- d-----w c:\program files\Fichiers communs\Nokia
2009-03-12 18:44 . 2009-03-12 18:42 -------- d-----w c:\program files\DIFX
2009-03-12 18:43 . 2009-03-12 18:43 -------- d-----w c:\program files\Fichiers communs\PCSuite
2009-03-12 18:42 . 2009-03-12 18:41 -------- d-----w c:\program files\PC Connectivity Solution
2009-03-09 03:19 . 2008-12-17 18:23 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 08:43 . 2006-11-09 18:31 -------- d-----w c:\program files\SokkerViewer
2009-03-08 08:20 . 2009-03-08 08:20 56 ---ha-w c:\windows\system32\ezsidmv.dat
2009-03-08 08:15 . 2009-03-08 08:15 -------- d-----w c:\program files\Fichiers communs\Skype
2009-03-08 08:15 . 2009-03-08 08:15 -------- d-----r c:\program files\Skype
2009-03-06 14:20 . 2004-01-17 09:49 286720 ----a-w c:\windows\system32\pdh.dll
2009-03-06 10:13 . 2009-01-17 19:12 -------- d-----w c:\program files\HomePlayer
2009-03-03 00:13 . 2004-07-07 16:59 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 17:10 . 2004-08-19 23:09 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-14 12:40 . 2008-10-28 13:16 1026 ----a-w c:\windows\system32\ealregsnapshot1.reg
2009-02-09 14:05 . 2004-01-17 09:49 1846912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:23 . 2002-08-29 11:42 2025984 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:23 . 2002-08-29 11:42 2147328 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:23 . 2004-01-17 09:49 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2004-01-17 09:49 735744 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2004-04-27 09:12 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:53 . 2004-01-17 09:49 739840 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:53 . 2004-01-17 09:48 685568 ----a-w c:\windows\system32\advapi32.dll
2009-02-06 10:39 . 2004-01-17 09:49 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:58 . 2004-01-17 09:49 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-27 1601304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Cmaudio"="cmicnfg.cpl" - c:\windows\CMICNFG.CPL [2003-12-11 2453504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-27 07:08 10520 ----a-w c:\windows\system32\avgrsstx.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ 'autocheck autochk *'
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Wireless Configuration Utility HW.32.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Wireless Configuration Utility HW.32.lnk
backup=c:\windows\pss\Wireless Configuration Utility HW.32.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Utilitaires\\Emule\\Emule\\emule.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Gaming Zone\\zclient.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Valve\\Steam\\Steam.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\toki127\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Utilitaires\\WinAmp 5.01\\Winamp 5.01 Pro\\Winamp\\winamp.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\toki127\\half-life 2 deathmatch\\hl2.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\system32\\svchost.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
"c:\\Program Files\\HomePlayer\\VLC\\vlc.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Fichiers communs\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 hidfltr;HID Filter Driver;c:\windows\system32\drivers\MWhid.sys [2004-11-03 13332]
R2 SolidWorks SolidNetWork License Manager;SolidWorks SolidNetWork License Manager; [x]
R3 Bacdri2sn;Bacdri2sn; [x]
R3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2004-12-29 167424]
S0 VOBID;VOBID;c:\windows\System32\DRIVERS\vobid.sys [2003-08-01 29239]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-01-27 325128]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-01-27 107272]
S1 vobcom;vobcom; [x]
S1 vobiw;vobiw; [x]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-27 903960]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-27 298264]
S2 litsgt;litsgt;c:\windows\system32\DRIVERS\litsgt.sys [2005-09-01 137344]
S2 tansgt;tansgt;c:\windows\system32\DRIVERS\tansgt.sys [2005-09-01 12032]
S3 cdrdrv;cdrdrv;c:\windows\system32\Drivers\Cdrdrv.sys [2004-02-03 62976]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2009-03-13 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2006\SystemOptimizer.exe [2005-09-01 05:27]
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Télécharger avec &BitSpirit
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: DirectAnimation Java Classes
DPF: fdjeux - hxxps://www.fdjeux.net/classes/fdjeux.cab
DPF: Interface Chat Wanadoo - hxxp://chat10.x-echo.com/version6/Applet/wchatsign.cab
DPF: Microsoft XML Parser for Java
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game18.zylom.servicesalacarte.wanadoo.fr/activex/zylomgamesplayer.cab
DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} - hxxp://f006.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
DPF: {FD40EC41-D860-4579-8BA4-52671A45C71C} - hxxp://images.goa.com/it/Woo2/fr/chat/nPaxChat.cab
FF - ProfilePath - c:\documents and settings\Marie\Application Data\Mozilla\Firefox\Profiles\yilwlg9b.Dijon\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.orange.fr/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA2&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-29 20:24
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-4227570477-946958389-1760926299-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-4227570477-946958389-1760926299-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:72,07,72,1c,79,5f,6c,37,40,d1,58,6b,09,91,f9,9c,c4,09,a9,81,eb,03,6f,
06,a5,23,71,52,3a,8e,e0,d2,94,5c,4a,bc,65,f1,32,5a,2d,fa,a8,2a,e9,3e,b9,0a,\
"??"=hex:e7,bf,49,2a,ff,46,8a,1e,33,b6,5c,8a,94,ea,fa,42
[HKEY_USERS\S-1-5-21-4227570477-946958389-1760926299-1006\Software\SecuROM\License information*]
"datasecu"=hex:72,5e,ac,a2,ca,ab,bf,35,bb,1c,80,d0,59,72,f6,a5,cb,82,3e,ef,9d,
f7,48,84,67,6a,7f,24,f4,d2,42,4e,fc,1c,bf,33,c2,2b,04,0f,3e,f5,ef,ac,20,05,\
"rkeysecu"=hex:eb,13,c8,93,1f,9e,ea,1c,f6,04,3c,dd,ca,82,10,b2
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3900)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_fre.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\Office10\msohev.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\windows\system32\Crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\progra~1\MICROS~4\rapimgr.exe
.
**************************************************************************
.
Heure de fin: 2009-04-29 20:32 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-29 18:32
Avant-CF: 58 285 084 672 octets libres
Après-CF: 58 971 541 504 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn
269 --- E O F --- 2009-04-15 01:11
ca veut dire qu'il y a encore des infections?
quelle est la suite du programme?
merci beaucoup de ton aide!